Forra

Privacy Policy

Last Updated: 2026-05-26 · Version v1.0

1. Who is the data controller?

The data controller for Forra is:

Michael Salah Milik Andrawos
Bienengasse 9/22, 8020 Graz
Austria
Email: [email protected]

You can reach us in English, German, or Arabic.

2. What data we collect and why

We collect only the data Forra needs to function. Every item below is named, justified, and tied to a legal basis under GDPR Article 6(1).

Data category Why we collect it Legal basis (Art. 6(1)) Retention
Account credentials (email, hashed password)Authenticate you; restore your sessions(b) contract performanceAccount lifetime + 24h post-deletion
Family memberships + display nameFamily-scoped data isolation(b) contract performanceAccount lifetime + 24h post-deletion
Shopping list items + checked statusCore product feature(b) contract performanceAccount lifetime + 24h post-deletion (items added by other family members survive on the shared list)
Expense entries (amount, category, date, note)Core product feature + AI recap input(b) contract performanceAccount lifetime + 24h post-deletion; invoice-relevant entries retained 7 years per Austrian Tax Code § 132 BAO
Income entriesCore product feature(b) contract performanceSame as expenses
Recurring expense + income rulesAuto-post automation(b) contract performanceAccount lifetime + 24h post-deletion
Voice recordings (microphone audio)Speech-to-text transcription(a) your explicit consent — one-time JIT modalNot retained — discarded immediately after one transcription request
Voice transcripts (text result)Display + intent extraction(a) your explicit consentAccount lifetime + 24h post-deletion
Voice & AI consent flagRemember whether you accepted the one-time JIT consent so we don't re-prompt(a) your explicit consent (state of)Account lifetime + 24h post-deletion; revokable anytime via Settings → Privacy → Voice & AI
AI summary cacheRecap result memoization(b) contract performanceSame as expenses
Crash reportsBug detection + diagnosis(f) legitimate interest — opt-out anytime via Settings → Privacy90 days at Sentry, then aggregated
Push notification tokensDeliver notifications you opted into(a) consent (OS-level prompt)Until you rotate the token or delete your account
IP-based approximate-location (city/country)Password-change email recognition signal(f) legitimate interestNot stored after the password-change email is sent
Subscription stateGate AI features behind your paid subscription(b) contract performanceSubscription lifetime + 30 days for fraud-investigation audit
Account-deletion audit logFraud investigation + GDPR audit trail(f) legitimate interest30 days from deletion confirmation

What we do NOT collect: location coordinates, contacts, photos, files outside Forra, advertising identifiers, browsing history, or behavior on other apps. We do not embed third-party analytics or tracking pixels in our mobile app or this website.

3. Sub-processors

Forra uses these third-party services to deliver the product. Each has a signed Data Processing Agreement with Forra under GDPR Art. 28. Transfers to US-based sub-processors rely on the EU Standard Contractual Clauses (Art. 46) and supplementary measures as required by the Schrems II ruling.

Sub-processorCountryRoleDPA
Supabase, Inc.EU (Frankfurt)Database, authentication, edge functions, file storagesupabase.com/legal/dpa
OpenAI, LLCUnited StatesVoice transcription (Whisper) + intent extraction (GPT-4o-mini)openai.com/policies/data-processing-addendum
Resend, Inc.United StatesTransactional email deliveryresend.com/legal/dpa
Functional Software, Inc. (Sentry)United StatesCrash reporting (opt-out anytime)sentry.io/legal/dpa
RevenueCat, Inc.United StatesSubscription billing receipts + webhook deliveryrevenuecat.com/dpa
ipapi.coUnited StatesIP-based approximate location for password-change emailsipapi.co/privacy

4. Voice input and AI (EU AI Act Art. 50)

When you use Forra's voice input feature:

Voice input is part of Forra's optional paid subscription (€4.99/month or €49.99/year). If you do not subscribe, the voice button does not appear.

5. Account deletion

You can delete your account anytime from Settings → Account → Delete account inside the Forra app. We commit to:

6. Your rights under GDPR

You have these rights regarding your personal data:

To exercise any of these rights, email [email protected]. We will respond within 30 days per Art. 12(3).

7. Right to complain

If you believe Forra is mishandling your data, you can lodge a complaint with the Austrian data protection authority:

Österreichische Datenschutzbehörde
Barichgasse 40-42, 1030 Wien, Austria
www.dsb.gv.at

8. Breach notification

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, Forra commits to notifying:

9. Automated decision-making

Forra does not make any solely-automated decisions about you that produce legal or similarly significant effects. The AI recap is informational only and does not change any state without your action; voice input always returns a transcript for your manual confirmation before writing to your data.

10. Changes to this policy

When we materially update this policy, we will notify you in-app and via email at least 30 days before the changes take effect, per Art. 13(3). The current version + "Last Updated" date appears at the top of this page.